apparmor-docs-3.1.7-150600.5.6.1<>,|hp9|nR+RP-DDҏݧHmp&ݙ-O%KZV?9"푸_)(b{tFcp[lrgw D.zIcYƇGjGi ndDW%qU7hx8`")a%؊`A'v\4H⮭#.Ұiv!e _E .FRb qp;?xd # B 5Ihnx         G  T    @P`(89h:^FGG\ H I XY\ ] ^bcdEeJfMlOud vz(,2tCapparmor-docs3.1.7150600.5.6.1AppArmor Documentation packageThis package contains documentation for AppArmor. This package is part of a suite of tools that used to be named SubDomain.hh04-ch1bSUSE Linux Enterprise 15SUSE LLC GPL-2.0-or-laterhttps://www.suse.com/Documentation/Otherhttps://launchpad.net/apparmorlinuxnoarche0-KIvʷA큤A큤hh heWeWeheWheWeWeWe18b7ab1776823a1e62a2d6db1bbbe51819f5732e89ca63a6dd3d540e629a42030a0adfab04b7755e093632fab7b8ab2adea32fc2eb640ec9586faa0cd2ebbd4ebeac1b7aa8497a59a81c4fc342ec5666f42e2dccea0104e188935ddd2137815d383e3f1c2fd71198fe319a325fbb9a2068dd73b2609e27db150d3aeddd9ed06afaf9108909890bb258f3dadbbd113fb35878c5f106a107850d33d62c851288d5e33ae4afd85d4e8a3a0f579068ca74e1686ba4651958a25e6792c6e1226f58dbe26924e382467ea63dd33229f07de8c3503ef5eac61cad007103e59e545bfb065b734a62259324cfd147c49382f1f4d2b4389cfaffbb1052eea742c669224001e91ac861de966cac00dd5711c9742ff2bfa9793a2848b5ae04c406fa888fbc6rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootapparmor-3.1.7-150600.5.6.1.src.rpmapparmor-docs    rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.3hg@e@ee}@eԔ@eԔ@e@ee@eKx@eKx@ev@d@d7d@ddtdS@cccױ@c@c@c|c@c Xcb{@bb@bޅbVb@b@b{@bwbk@bi0@bZbV@bT@bRbBb<]@b@a7aZ@ap@aabaim@aEaaua $@`#@` @````_@`%@`!'`>` @__ǁ_ǁ_Q_h__@_~@_[f_P_-B@_@^m@^@^<@^j$@^,-]҇]o](]K@]]@\\@\ \\v{\I\ include in apache extra profile optional to avoid problems with empty profile directory (boo#1178527)- prepare usrmerge (boo#1029961) * use %_pamdir- update to AppArmor 3.0.1 - minor additions to profiles and abstractions - some bugfixes in libapparmor, apparmor_parser and the aa-* utils - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_3.0.1 for the detailed upstream changelog - removed upstream(ed) patches: - changes-since-3.0.0.diff - extra-profiles-fix-Pux.diff - utils-fix-hotkey-conflict.diff- Use apache provided variables for the module_directry: + Use %apache_libexecdir + Add apache-rpm-macros BuildRequires- add utils-fix-hotkey-conflict.diff to fix a hotkey conflict in de, id and sv translations (and fix the test) (MR 675) - add extra-profiles-fix-Pux.diff to fix an inactive profile - prevents a crash in aa-logprof and aa-genprof when creating a new profile (MR 676)- update to AppArmor 3.0.0 - introduce feature abi declaration in profiles to enable use of new rule types (for openSUSE: dbus and unix rules) - support xattr attachment conditionals - experimental support for kill and unconfined profile modes - rewritten aa-status (in C), including support for new profile modes - rewritten aa-notify (in python), finally dropping the perl requirement at runtime - new tool aa-features-abi for extracting feature abis from the kernel - update profiles to have profile names and to use 3.0 feature abi - introduce @{etc_ro} and @{etc_rw} profile variables - new profile for php-fpm - several updates to profiles and abstractions (including boo#1166007) - fully support 'include if exists' in the aa-* tools - rewrite handling of alias, include, link and variable rules in the aa-* tools - rewrite and simplify log handling in the aa-logprof and aa-genprof - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_3.0 for the detailed upstream changelog - patches: - add changes-since-3.0.0.diff with upstream fixes since the 3.0.0 release up to 3e18c0785abc03ee42a022a67a27a085516a7921 - drop upstreamed usr-etc-abstractions-base-nameservice.diff - drop 2.13-only libapparmor-so-number.diff - refresh apparmor-enable-profile-cache.diff - partially upstreamed - update apparmor-samba-include-permissions-for-shares.diff and apparmor-lessopen-profile.patch - switch to "include if exists" - apparmor-lessopen-profile.patch: add abi rule to lessopen profile - refresh apparmor-lessopen-nfs-workaround.diff - move away very loose apache profile that doesn't even match the apache2 binary path in openSUSE to avoid confusion (boo#872984) - move rewritten aa-status from utils to parser subpackage - add aa-features-abi to parser subpackage - replace perl and libnotify-tools requires with requiring python3-notify2 and python3-psutil (needed by the rewritten aa-notify) - drop ancient cleanup for /etc/init.d/subdomain from parser %pre - drop (never enabled) conditionals to build with python2 and to build the python-apparmor subpackage (upstream dropped python2 support) - drop setting PYTHON and PYTHON_VERSIONS env variable, no longer needed - set PYFLAKES path for utils check - add precompiled_cache build conditional to allow faster local builds without using kvm - remove duplicated BuildRequires: swig- update to AppArmor 2.13.5 - add missing permissions to several profiles and abstractions - bugfixes in parser and tools - fix two potential build failures in libapparmor - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_2.13.5 for the detailed upstream changelog - remove upstream(ed) patches - changes-since-2.13.4.diff - abstractions-X-xauth-mr582.diff - sevdb-caps-mr589.diff - libvirt-leaseshelper.patch - cap_checkpoint_restore.diff - add libapparmor-so-number.diff to fix libapparmor so version (!658)- add CAP_CHECKPOINT_RESTORE to severity.db (MR 656, cap_checkpoint_restore.diff)- %service_del_postun_without_restart only works for Tumbleweed, keep using DISABLE_RESTART_ON_UPDATE for Leap 15.x- Make use of %service_del_postun_without_restart And stop using DISABLE_RESTART_ON_UPDATE as this interface is obsolete.- libvirt-leaseshelper.patch: add /usr/libexec as a path to the libvirt leaseshelper script (jsc#SLE-14253)- sevdb-caps-mr589.diff: add new capabilities CAP_BPF and CAP_PERFMON to severity.db (lp#1890547)- add abstractions-X-xauth-mr582.diff to allow reading the xauth file from its new sddm location (boo#1174290, boo#1174293)- add changes-since-2.13.4.diff with upstream changes and fixes since 2.13.4 up to 5f61bd4c: - add several abstractions related to xdg-open: dbus-network-manager-strict, exo-open, gio-open, gvfs-open, kde-open5, xdg-open - introduce @{run} variable - update dnsmasq and winbindd profile - update mdns, mesa and nameservice abstraction - some bugfixes in the aa-* tools, including a remote bugfix in the YaST AppArmor module (boo#1171315) - drop upstream(ed) patches (now part of changes-since-2.13.4.diff): - make-4.3-capabilities.diff - make-4.3-capabilities-vim.diff - make-4.3-fix-utils-network-test.diff - make-4.3-network.diff - abstractions-add-etc-mdns.allow-to-etc-apparmor.d-abstractions-mdns.patch - apply usr-etc-abstractions-base-nameservice.diff only for Tumbleweed, but not for Leap 15.x where it's not needed - refresh usr-etc-abstractions-base-nameservice.diff- Add abstractions-add-etc-mdns.allow-to-etc-apparmor.d-abstractions-mdns.patch (bsc#1168306)- fix build with make 4.3 by backporting some commits from upstream master (boo#1167953): - make-4.3-capabilities.diff - make-4.3-capabilities-vim.diff - make-4.3-network.diff - make-4.3-fix-utils-network-test.diff- update to AppArmor 2.13.4 - several abstraction updates (including boo#1153162) - disallow writing to fontconfig cache in abstractions/fonts - some bugfixes in the aa-* tools - fix log parsing for logs with an embedded newline - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_2.13.4 for the detailed upstream changelog - drop upstreamed patches: - abstractions-ssl-certbot-paths.diff - apparmor-krb5-conf-d.diff - libapparmor-python3.8.diff - usr-etc-abstractions-authentification.diff - refresh usr-etc-abstractions-base-nameservice.diff- add usr-etc-abstractions-base-nameservice.diff to adjust abstractions/base and nameservice for /usr/etc/ (boo#1161756)- Properly pull in full python3 interpreter- add libapparmor-python3.8.diff to fix building the libapparmor python bindings (deb#943657)- add usr-etc-abstractions-authentification.diff to allow reading /usr/etc/pam.d/* and some other authentification-related files (boo#1153162)- add abstractions-ssl-certbot-paths.diff - add certbot paths to abstractions/ssl_certs and abstractions/ssl_keys- add apparmor-krb5-conf-d.diff for kerberos client- update to 2.13.3 - profile updates for dnsmasq, dovecot, identd, syslog-ng - new "lsb_release" profile (only used when using "Px -> lsb_release") - fix buggy syntax in tunables/share - several abstraction updates - parser: fix "Px -> foo-bar" (the "-" was rejected before) - several bugfixes in aa-genprof and aa-logprof - some fixes in cache handling - see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.13.3 for the detailed upstream changelog - drop upstream(ed) patches: - apparmor-nameservice-resolv-conf-link.patch - profile_filename_cornercase.diff - dnsmasq-libvirtd.diff - dnsmasq-revert-alternation.diff - usrmerge-fixes.diff - libapparmor-swig-4.diff - re-number remaining patches- add upstream libapparmor-swig-4.diff: fix libapparmor tests with swig 4.0 (boo#1135751)- Disable LTO (boo#1133091).- update lessopen.sh profile for usrMerge (bash and tar) (boo#1132350)- add usrmerge-fixes.diff: fix test failures when /bin/sh is handled by update-alternatives (boo#1127877)- add dnsmasq-revert-alternation.diff: revert path alternation in dnsmasq profile and re-add peer=/usr/sbin/libvirtd rules to avoid breaking libvirtd (boo#1127073)- add dnsmasq-libvirtd.diff: allow peer=libvirtd in the dnsmasq profile to match the newly added libvirtd profile name (boo#1118952#c3)- Use %license instead of %doc [bsc#1082318]- add apparmor-lessopen-nfs-workaround.diff: allow network access in lessopen.sh for reading files on NFS (workaround for boo#1119937 / lp#1784499)- add profile_filename_cornercase.diff: drop check that lets aa-logprof error out in a corner-case (log event for a non-existing profile while a profile file with the default filename for that non-existing profile exists) (boo#1120472)- netconfig: write resolv.conf to /run with link to /etc (fate#325872, boo#1097370) [patch apparmor-nameservice-resolv-conf-link.patch]- update to AppArmor 2.13.2 - add profile names to most profiles - update dnsmasq profile (pid file and logfile path) (boo#1111342) - add vulkan abstraction - add letsencrypt certificate path to abstractions/ssl_* - ignore *.orig and *.rej files when loading profiles - fix aa-complain etc. to handle named profiles - several bugfixes and small profile improvements - see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.13.2 for the detailed upstream changelog - remove upstreamed fix-syntax-error-in-rc.apparmor.functions.patch- update to 2.13.1 - add qt5 and qt5-compose-cache-write abstractions - add @{uid} and @{uids} kernel var placeholders - several profile and abstraction updates - ignore "abi" rules in parser and tools (instead of erroring out) - utils: fix overwriting of child profile flags if they differ from the main profile - several bugfixes (including boo#1100779) - see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.13.1 for the detailed upstream changelog - remove upstream(ed) patches: - aa-teardown-path.diff - fix-apparmor-systemd-perms.diff - logprof-skip-cache-d.diff - fix-samba-profiles.patch - make-pyflakes-happy.diff - dnsmasq-Add-permission-to-open-log-files.patch - refresh apparmor-samba-include-permissions-for-shares.diff - add fix-syntax-error-in-rc.apparmor.functions.patch- update rpmlintrc: - whitelist .features file which is part of the pre-compiled cache - comment out filters for the disabled tomcat_apparmor subpackage- Backport dnsmasq fix: 025c7dc6 - dnsmasq-Add-permission-to-open-log-files.patch (boo#1111342)- add make-pyflakes-happy.diff to fix an unused variable (SR 629206)- add fix-samba-profiles.patch - smbd loads new shared libraries. Allow winbindd to access new kerberos credential cache location (boo#1092099)- exclude the /etc/apparmor.d/cache.d/ directory from aa-logprof parsing (logprof-skip-cache-d.diff)- add fix-apparmor-systemd-perms.diff - fix permissions of /lib/apparmor/apparmor.systemd (boo#1090545)- create and package precompiled cache (/usr/share/apparmor/cache, read-only) (boo#1069906, boo#1074429) - change (writeable) cache directory to /var/cache/apparmor/ - with the new btrfs layout, the only reason for using /var/lib/apparmor/cache/ (which was "it's part of the / subvolume") is gone, and /var/cache makes more sense for the cache - adjust parser.conf (via apparmor-enable-profile-cache.diff) to use both cache locations - clear cache also in %post of abstractions package- update to AppArmor 2.13 - add support for multiple cache directories and cache overlays (boo#1069906, boo#1074429) - add support for conditional includes in policy - remove group restrictions from aa-notify (boo#1058787) - aa-complain etc.: set flags for profiles represented by a glob - aa-status: split profile from exec name - several profile and abstraction updates - see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.13 for the detailed upstream changelog - drop upstreamed patches and files: - aa-teardown - apparmor.service - apparmor.systemd - 32-bit-no-uid.diff - disable-cache-on-ro-fs.diff - dovecot-stats.diff - parser-write-cache-warn-only.diff - set-flags-for-profiles-represented-by-glob.patch - fix-regression-in-set-flags.patch - drop spec code that handled installing aa-teardown, apparmor.service and apparmor.systemd (now part of upstream Makefile) - simplify "make -C profiles parser-check" call (upstream Makefile bug that required to call "cd" was fixed) - add aa-teardown-path.diff - install aa-teardown in /usr/sbin/ - move 'exec' symlink to parser package (belongs to aa-exec)- Set flags for profiles represented by glob (bsc#1086154) set-flags-for-profiles-represented-by-glob.patch fix-regression-in-set-flags.patch- add dovecot-stats.diff: - add dovecot/stats profile and allow dovecot to run it (boo#1088161) - allow dovecot/auth to write /run/dovecot/old-stats-user (part of boo#1087753) - update 32-bit-no-uid.diff with upstream fix- Change of path of rpm in lessopen.sh (boo#1082956)- add disable-cache-on-ro-fs.diff - disable write cache if filesystem is read-only and don't bail out (bsc#1069906, bsc#1074429)- add parser-write-cache-warn-only.diff to make cache write failures a warning instead of an error (boo#1069906, boo#1074429) - reduce dependeny on libnotify-tools (used by aa-notify -p) to "Suggests" to avoid pulling in several Gnome packages on servers (boo#1067477)- update to AppArmor 2.12 - add support for 'owner' rules in aa-logprof and aa-genprof - add support for includes with absolute path in aa-logprof etc. (lp#1733700) - update aa-decode to also decode PROCTITLE (lp#1736841) - several profile and abstraction updates, including boo#1069470 - preserve errno across aa_*_unref() functions - see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.12 for the detailed upstream changelog - drop upstreamed patches: - read_inactive_profile-exactly-once.patch - utils-fix-sorted-save_profiles-regression.diff - lessopen profile: change all 'rix' rules to 'mrix' - add 32-bit-no-uid.diff to fix handling of log events without ouid on 32 bit systems - no longer package static libapparmor.a- update to AppArmor 2.11.95 aka 2.12 beta1 - add JSON interface to aa-logprof and aa-genprof (used by YaST) - drop old YaST interface code - update audio, base and nameservice abstractions - allow @{pid} to match 7-digit pids - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_11_95 for the detailed upstream changelog - drop upstreamed patches - apparmor-yast-cleanup.patch - apparmor-json-support.patch - nameservice-libtirpc.diff - drop obsolete perl modules (YaST no longer needs them) - drop patches that were only needed by the obsolete perl modules: - apparmor-utils-string-split - apparmor-abstractions-no-multiline.diff - drop profiles-sockets-temporary-fix.patch - obsoleted by a fix in apparmor_parser - refresh utils-fix-sorted-save_profiles-regression.diff - add aa-teardown (new script to unload all profiles) - make ExecStop in apparmor.service a no-op (workaround for a systemd restriction, see boo#996520 and boo#853019 for details) - lessopen profile: allow capability dac_read_search and dac_override, allow groff to execute several helpers (boo#1065388)- read_inactive_profile-exactly-once.patch (bsc#1069346) Perform reading of inactive profiles exactly once.- update to AppArmor 2.11.1 - add permissions to several profiles and abstractions (including lp#1650827 and boo#1057900) - several fixes in the aa-* tools (including lp#1689667, lp#1628286, lp#1661766 and boo#1062667) - fix downgrading/converting of 'unix' rules (will be supported in kernel 4.15) to 'network unix' rules in apparmor_parser (boo#1061195) - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_11_1 for upstream changelog - remove upstream(ed) patches - upstream-changes-r3616..3628.diff - upstream-changes-r3629..3648.diff - parser-tests-dbus-duplicated-conditionals.diff - apparmor-fix-podsyntax.patch - sshd-profile-drop-local-include-r3615.diff - refresh apparmor-yast-cleanup.patch - add utils-fix-sorted-save_profiles-regression.diff to fix a regression in displaying the "changed profiles" list in aa-logprof- add nameservice-libtirpc.diff to fix NIS/YP logins (boo#1062244)- profiles-sockets-temporary-fix.patch to cater to nameservices with the new sockets mediation, until unix rules are upstreamed (boo#1061195)- add apparmor-fix-podsyntax.patch from mailing list to fix compilation with perl 5.26- do not require exact X.Y version of "python3" - require also matching python(abi) which is arguably more important- don't rely on implementation details for reload in %post- add JSON support. Required for FATE#323380. (apparmor-yast-cleanup.patch, apparmor-json-support.patch)- add upstream-changes-r3629..3648.diff: - preserve unknown profiles when reloading apparmor.service (CVE-2017-6507, lp#1668892, boo#1029696) - add aa-remove-unknown utility to unload unknown profiles (lp#1668892) - update nvidia abstraction for newer nvidia drivers - don't enforce ordering of dbus rule attributes in utils (lp#1628286) - add --parser, --base and --Include option to aa-easyprof to allow non-standard paths (useful for tests) (lp#1521031) - move initialization code in apparmor.aa to init_aa(). This allows to run all utils tests even if /etc/apparmor.d/ or /sbin/apparmor_parser don't exist. - several improvements in the utils tests - drop upstreamed python3-drop-re-locale.patch - no longer delete/skip some of the utils tests (to allow this, add parser-tests-dbus-duplicated-conditionals.diff) - add var.mount dependeny to apparmor.service (boo#1016259#c34)- Cleanup spec file: - don't use insserv if we afterwards call systemd, this can have bad side effects - remove dead code - remove now obsolete 'distro' checks - Replace init.d script with new wrapper working with systemd- add python3-drop-re-locale.patch: remove deprecated re.LOCALE flag in Python UI as it was dropped from Python 3.6 (lp#1661766)- Fix RPM groups- add upstream-changes-r3616..3628.diff: - update abstractions/base, abstractions/apache2-common and dovecot profiles - merge ask_the_questions() of aa-logprof and aa-mergeprof - pass LDFLAGS when building parser, libapparmor perl bindings and pam_apparmor - adjust deleting the cache in profiles %post to the new cache location - silence errors when deleting the cache (boo#976914)- split libapparmor into separate spec to get rid of build loop involving mariadb, systemd, apparmor, libapr and mariadb again (see the discussion in SR 448871 for details) - libapparmor.spec is based on the AppArmor 2.11 apparmor.spec, but with minimum BuildRequires- update to AppArmor 2.11.0 - apparmor_parser now supports parallel compiles and loads - add full support for dbus, ptrace and signal rules and events to the utils - full rewrite of the file rule handling in the utils - lots of improvements and fixes - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_11 for the detailed changelog - patches: - add sshd-profile-drop-local-include-r3615.diff to fix 'make check' - drop aa-unconfined-fix-netstat-call-2.10r3380.diff, no longer needed - refresh apparmor-abstractions-no-multiline.diff - refresh apparmor-samba-include-permissions-for-shares.diff - spec changes: - aa-unconfined switched to using ss (from iproute2), adjust Recommends: - move libapparmor to /usr/lib*/ - drop %if %suse_version checks for 12.x - change several Obsoletes from %version to < 2.9. Those package names weren't used since years, and 2.9 is still a careful choice - include apparmor.service independent of %suse_version - techdoc.pdf is now shipped in upstream tarball to reduce BuildRequires - drop latex2html, texlive-* and w3m BuildRequires - techdoc.txt and techdoc.html not included, drop them from the package - run most of utils/ make check (some tests expect /etc/apparmor.d/ and /sbin/apparmor_parser to exist, skip them) - BuildRequires python3-pyflakes (utils tests) and dejagnu (libapparmor tests) - drop sed'ing python3 into aa-* shebang (upstreamed) - build binutils - aa-exec is now written in C and lives in /usr/bin/, move it to the apparmor_parser package and create a compability symlink in /usr/sbin/ - aa-exec manpage moved to section 1 - aa-enabled is a small new tool to find out if AppArmor is enabled - package new aa_stack_profile(2) manpage- change /etc/apparmor.d/cache symlink to /var/lib/apparmor/cache/. This is part of the root partition (at least with default partitioning) and should be available earlier than /var/cache/apparmor/ (boo#1015249, boo#980081, bsc#1016259) - add dependency on var-lib.mount to apparmor.service as safety net- update to AppArmor 2.10.2 maintenance release - lots of bugfixes and profile updates (including boo#1000201, boo#1009964, boo#1014463) - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_10_2 for details - add aa-unconfined-fix-netstat-call-2.10r3380.diff to fix a regression in aa-unconfined - drop upstream(ed) patches: - changes-since-2.10.1--r3326..3346.diff - changes-since-2.10.1--r3347..3353.diff - libapparmor-fix-import-path.diff (upstream fix is slightly different) - nscd-var-lib.diff - refresh apparmor-abstractions-no-multiline.diff- add nscd-var-lib.diff to allow /var/lib/nscd/ in the nscd profile and abstractions/nameservice (path changed in latest nscd in Tumbleweed)- add changes-since-2.10.1--r3347..3353.diff with upstream changes and fixes in the 2.10 branch, including - allow writing *.qf files (for disk-based buffering) in syslog-ng profile - add several permissions to the dovecot profiles (deb#835826) - add a missing path in the traceroute profile- add changes-since-2.10.1--r3326..3346.diff with upstream changes and fixes since the 2.10.1 release, including - allow dac_override in winbindd profile (boo#990006#c5) - allow mr for /usr/lib*/ldb/*.so in samba abstractions (needed since Samba 4.4.x, boo#990006) - abstractions/nameservice: also support ConnMan-managed resolv.conf - let aa-genprof ask about profiles in extra dir (again) - fix aa-logprof "add hat" endless loop (lp#1538306) - honor 'chown' file events in logparser.py - ignore log file events with a request mask of 'send' or 'receive' because they are actually network events (lp#1577051, lp#1582374) - accept hostname with dots when parsing logs (lp#1453300 comments #1 and #2) - fix python LibAppArmor import failures with swig > 3.0.8 (boo#987607) (libapparmor-fix-import-path.diff) - refresh apparmor-abstractions-no-multiline.diff - drop upstreamed profiles-ping-inet6-r3449.diff - add %check section - runs libapparmor (including swig bindings), parser and profiles tests - add BuildRequires: perl(Locale::gettext) - needed for parser tests- add profiles-ping-inet6-r3449.diff - latest ping also does IPv6 (boo#980596)- update to AppArmor 2.10.1 (2.10 branch r3326): - fix incorrect output of child profile names (apparmor_parser -N) which caused 'rcapparmor reload' to remove child profiles and hats (lp#1551950) - fix a crash in aa-logprof / logparser.py for change_hat log events (lp#1523297) and log events that look like file events, but aren't (lp#1540562, lp#1525119, lp#1466812) - write unix rules when saving a profile (lp#1522938, boo#954104#c3) - several fixes for variable handling in aa-logprof - map c (create) log events to w instead of a - add python to the "no Px rule" list in logprof.conf - let aa-logprof check for duplicate profiles - let aa-status work without the apparmor.fail python module (boo#971917, lp#1480492) - add permissions in several profiles (including boo#948584, boo#948753, boo#954959, boo#954958, boo#971790, boo#964971, boo#921098, boo#923201 and boo#921098#c15). - and many more fixes, see the full changelog at http://wiki.apparmor.net/index.php/ReleaseNotes_2_10_1 - drop upstream(ed) patches: - fix-initscript-aa_log_end_msg.diff - syslog-ng-profile-boo948584.diff - upstream-profile-updates-r3205-3241.diff - refresh patches: - apparmor-abstractions-no-multiline.diff - apparmor-samba-include-permissions-for-shares.diff - drop libapparmor autogen.sh call (broke the build) and remove libtool BR- add syslog-ng-profile-boo948584.diff - add several permissions needed by latest syslog-ng (boo#948584, boo#948753) - add upstream-profile-updates-r3205-3241.diff with several profile updates: - add /usr/share/locale-bundle/** to abstractions/base - allow dnsmask to use /bin/sh (boo#940749) and /bin/dash - allow dovecot imap to read /run/dovecot/mounts - allow avahi-daemon to write to /run/systemd/notify - allow ntpd to read $PATH directory listings (boo#945592, boo#948752) - update dhclient profile - allow skype to read @{PROC}/@{pid}/net/dev (boo#939568) - and some other small updates - drop upstreamed apparmor-winbindd-r3213.diff (included in the upstream-profile-updates patch)- netstat moved to net-tools-deprecated in Tumbleweed (boo#944904)- add apparmor-winbindd-r3213.diff - add missing k permissions for /etc/samba/smbd.tmp/msg/* in winbindd profile (boo#921098 #c15..19)- add fix-initscript-aa_log_end_msg.diff - fixes ugly initscript output (boo#862170)- update to AppArmor 2.10 (trunk r3205) - profile names can now contain variables - improved profile compile time in apparmor_parser - lots of improvements, refactoring and bugfixes in the aa-* tools - new apis for managing and loading profile caches into the kernel in libapparmor - lots of profile updates - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_10 for the complete changelog with more details - add new apparmor_private.h and the aa_query_label(2), aa_features(3), aa_kernel_interface(3), aa_policy_cache(3), aa_splitcon(3) manpages to libapparmor-devel - drop apparmor-2.5.1-edirectory-profile patch - it's most probably no longer needed (see boo#621394 for details) - drop upstreamed samba-4.2-profiles.diff - refresh apparmor-samba-include-permissions-for-shares.diff- systemd-rpm-macros and %systemd_requires were at the wrong place, move them to the parser package (boo#931792)- update to AppArmor 2.9.2 (2.9 branch r2911) - lots of bugfixes in the parser and the aa-* tools (including boo#918787) - update dovecot and dnsmasq profiles and several abstractions (including boo#911001) - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_9_2 for the full changelog - remove upstream(ed) patches apparmor-changes-since-2.9.1.diff and apparmor-fix-stl-ostream.diff - replace GPG key with new AppArmor GPG signing key, see https://launchpad.net/apparmor/+announcement/13404- make sure %service_del_postun doesn't call systemctl try-restart (boo#853019, bare systemd edition) - add samba-4.2-profiles.diff: update samba (winbindd and nmb) profiles for samba 4.2 (boo#921098, boo#923201)- only install apparmor.service for openSUSE > 13.2- Add a native systemd unit which *at the moment* only wraps/masks the early boot script.- add apparmor-fix-stl-ostream.diff which fixes odd uses of std::ostream which are not valid. Fixes build with GCC 5- allow lessopen.sh to run /usr/bin/unzip-plain (boo#906858)- add Requires: python3 to python3-apparmor package - readline isn't part of python3-base (boo#917577)- add apparmor-changes-since-2.9.1.diff with upstream fixes since the 2.9.1 release - update logparser.py to support changed syslog format (lp#1399027) - update usr.sbin.dovecot and usr.lib.dovecot.imap{, -login} profiles (lp#1296667) - update the mysqld profile - fix network rule description in apparmor.d(5) manpage - drop upstreamed dnsmasq-profile-fixes.patch - update expired GPG key- update to AppArmor 2.9.1 (2.9 branch r2831) - fix log parsing for 3.16 kernels and syslog-style logs (boo#905368) - several fixes and performance improvements in the aa-* utils - profile updates for dnsmasq (boo#907870), nscd (boo#904620#c14 and bnc#908856), useradd, sendmail, man and passwd - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_9_1 for full release notes - refresh dnsmasq-profile-fixes.patch- Fix dnsmasq profile to allow executing bash to run the --dhcp-script argument. Also fixed /usr/lib -> /usr/{lib,lib64} to get libvirt leasehealper script to run even on x86_64. dnsmasq-profile-fixes.patch. boo#911001- rename lessopen.sh profile file to usr.bin.lessopen.sh to match the script filename- add apparmor-lessopen-profile.patch: /usr/bin/lessopen.sh needs confinement. bnc#906858- delete cache in apparmor-profiles %post (workaround for bnc#904620#c8 / lp#1392042)- No longer perform gpg validation; osc source_validator does it implicit: + Drop gpg-offline BuildRequires. + No longer execute gpg_verify.- fix bashism in post script- update to AppArmor 2.9.0 (r2759) - change aa-mergeprof to the final commandline syntax - lots of bugfixes in the aa-* tools (bnc#900163, lp#1328707 and several bugs without a formal bugreport) - small additions to gnome, freedesktop.org, ubuntu-browsers.d/java and user-mail abstractions - fix mod_apparmor to not break basic auth - update perl modules to support signal, unix and ptrace rules (bnc#900013) - don't warn about rules not supported by the kernel - fix logging of "audit capability" (lp#1378091) - add support for the "hat" keyword in apparmor.vim - build html version of apparmor.vim manpage again (lp#1366572) - see also http://wiki.apparmor.net/index.php/ReleaseNotes_2_9_0 - update apparmor-abstractions-no-multiline.diff - remove upstreamed apparmor-profiles-ntpd-pid-location.diffh04-ch1b 1745392364 3.1.7-150600.5.6.1apparmorapparmor.vimapparmor-docsaa-teardown.8.htmlapparmor.7.htmlapparmor.cssapparmor.d.5.htmlapparmor.vim.5.htmlapparmor_parser.8.htmlapparmor_xattrs.7.htmltechdoc.pdf/usr/share//usr/share/apparmor//usr/share/doc/packages//usr/share/doc/packages/apparmor-docs/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:38382/SUSE_SLE-15-SP6_Update/108ff988527a5e410ebf430fd63f6431-apparmor.SUSE_SLE-15-SP6_Updatedrpmxz5x86_64-suse-linuxdirectoryASCII text, with very long linesXML 1.0 document, ASCII textXML 1.0 document, ASCII text, with very long linesASCII text*"sO˻Putf-8938bdf407102b7ef40452fadc9b567f46eabc24fb1849fb036ac59b1988d6e82?P7zXZ !t/Q]"k%R{_OdT8v%l_ciSm7XWQӮM3c5 E"BzW?|Ds ayhKP^ =߫0eTDE_Qb}@w|ڧnG&C/~6!!EQwWNRbgu8?w o6*x]M¯1yje45[CA[ezPg7f{5Ϩ׹ƸH&MSTe_VK G¾j95~@k2D:9ɤTOB?ЌRw{Vb9QYf@.et+J<y~!S}~-狯uR>ntA5֔M,Y'n 8M TA_Du%f2ViҺ|8Xy:ɇBʬWWB;_`?znV-RxWX"b#IًB7n}i ,\}0ʀԍ&+-OzvΛ(/Zrs)aLY*% xJK/yRD*Rx!go  N~a!kTWy nC4ĩ kn8 k/ !pG𓠪׵5V ;Q HeǺ* mAK`#iwKqSKX5-tkC?NXWbvU)IX~xecbQ~bVXb~^ةbI^94F\{&b|'[kK5X&#&#6XߙQz`#*iOPhH*4\ BxzjD9j_y;ydXXA|5ޟ9JS]!Nmn[:qGb-8)"ulk=5Ek COȐ҅êQZ< \IJ"9kj67;W Ѓ}z|Ix!z??/7@&k QK/SE $(6vL̀uJ}YQc&nj6܍/\B`BpQkUb|ŧ+$h=IM ?#X=^?$#Iub3njYˏfru4 9;1s֠?zp{X Ơ8{t6he7ЄQLWLT! [hbba/R n p>]ti* if]JK&LDΉ6'MޝxHO~.ۓ;-2Je?Gg5~T8U#{/d*-<*}ǟu8KNhhc{*Ldp}Vb?S =.AByԈ Ip.NPćVjjNczs1H?_ [ 4LF0}o}Up@!x`d6F25C:ˆ}N8:^6Tpl˞+l$(JLD+)yo1Nאo ) Je0=5 nYt@ڹKp>[",I`ANF}1c fyHB)!r&"M0 ĖFÁnGE>7Ljl=RϨOgηl i!O:;eR [X Z<ӮH1U J̇])26ĪG< ۚWNX&ïiJ |-'M5XwقӀڱaL2qG~X!.ib#Gk.<'sW<]hrrK)ZuT0eZpymk V9kQq_yZ%,w߉@ !6H{v7mqGYy1(OpZnmP>p8)=X^\2ގ1TMmNYAL/HJb;HR'7NWq"{ٙD`ru8_jlI?~hA`~cJfPZ- XUiʎw1%)! I6>ާgf9s}뮅%D(3CSn\Y vpxl"Ҏ_K/]HY;qSNUJy mV-IrCT^Y*ujL Eݞ9SřU@}VXީ6Đ@kU)d`J=>/H'=ћ1 y!'),Ql Hi< ƴi 3QÎTpgԶYc,[vi$0Z Hq6Msq0ƴ^.* k =&e[+?4Q^pfW(5hL@-FdQY!, *}ln$kduꕫ`-lF\52]W/i"/G(Ryh^[le^ %1찐^bH{.!b >[n_:ZD˔3FgUgX EKHf]J-@֨J=ɷ`CtHBYQͬTsϞ{WiAE$oيstwM/ҬcWmй6Mow(: >&F=R0:?~ᮓK|NͦtDf馁 w)djDzW+*REً'EK)dh>x#mO&u"o-;PΔu?c˚lg890^T5XCu8H_h'ig4:͓&SU/fq`8Yޘ}"2lbA2Ng_\5`xnY1n.T_Nmx!9ctfHDpd |lWĭS/j@.&1*aXwEBC>I/? h1g4' 2\b*U!ʊr9FRse^`vG,GO&0HB0':JA|$xQ^=Xܔ f-}ez+IP@E ZEFdMR¤/Y6DW Z4æ3A;WyvD1QGm("Lf]}[7rXHH `K|5fAqP׈J\8?(Z%5I@a;>,ue7_=eE`SFg].X$jK5>;Rb+r"rN)ne}C<d*| P >v5Ԥj֕o0=3 8 -.譳JglzAx왮ljz3}T8 p.>yD^u8 ͩl--RBs{ѕ~;3l(ݷ}I÷hHxT[R,yi 356QS~7RRL\$iȨi7I?$y Ȑ?X Kn* ?3Q}" UJ0/:T`eЛ72'xN(sg(S.2!~#R눂"}'Kיʵ-lS< ʹE>1aF6E6a|WKKlܿ?FSՎ'p (F'O^h 'q^ BY{O`yJ?^ym ^9H'e$0˗_Sٶ*wE(|pFm+#3L5Iwi(saOn.vSEWQ:#0zaOutFk#w#-I1DDW?Ԏ!/_o`խi#Qy˒\;7!1j7"),hD#/ut .kXճx.ZaD3o>F`ѱ >5 t!f5xJy! OZEH*'ǰ$97ڝLٲt.q#2ԕNzMpB G 7o__0Y,CO&yuTR-zK2T9/n˵]}qd<\v$&:/<{Nlh:es"2sMJ=g)ѕ=׀+< g=*BΉdLt%$S죎d~[XBY2d8a ҲEF)d1)z6 3ɁG=_ SAJH$SslE~Χ_ Y$5R\㋉{la{Jju k:3+b见BΩ5A/Iœ_i: 3+3Srvh䑚 9t^,Ńxr?[wKljNo+wxt ] P{25@>G5FʴCr5-'LB%P8u#Os]rwu ˺䬏/:آw;?;9)[>_)iqi)dd͈ղs8`]yAԦ_0g&ަ`-q| )>rY K_G8&e}}Yu;K$B ,ըWΗ} й_BҫU"7/:zܵ&zeM iomeT|3DU`Hks=y;U>)H 4kj)$%"(~xB<>* FiИs4P] 4[@#_I|^9$e:Tx'7&D?9g*XfG ^7g Zd*cѻ0#t!iNmV*.@R=9$4Ի$HՄt(GhX%/[ѧ"L"bQe.^._U^[CS-ٯ3LEjNj=W|m}Ypa [E4wǕ7ܼ0QXuv"WV{QғRn>e^_Sh6?R>XW%_,|v"peԵ$yI"7(>TV" !i^ .?%q^^5pdRqPLJFyz0T R&EqލczߣG aj; u4lQ NxraY>J)Қ &tnO2ՋvEcu;J7kˬ|^axN*>ޒMMWi`;OfY rDR~>p@'af/b+mͳUmz\ndTXշOdItcRYo} $kq,Z2J&`vǥjax2ʤ|ڌCy2UG߄mduGtĉ;n1=6*qI%ٴ|Vb)lHsŗ)-l>d 1_[?"ՈX14ocס؃jIa5 bAbЊ< r(Z +ȟBb]L%4ZĭJùbJJ72>_R=|Dϐ[C0Q܀e1|MP7{YZypwwl7]sCVC'm2K}Wycad.- +$V!و' ?8SxbC4q+](;m( Qߨ}OW^U=F@]tD~缑\R뀌M/cLȲ]W3 }(ER;!S`{CmJ&yبy%|'\IƯGg\ꪂP*.X@jw G~;&┵Y*#"$xءWEm {NE"P'9)W<!*`8/d5 O.z@CRv}vð^i~_: ^ڧBpòAW0R7x . XH{XUH\t@Y{aLjR2XR/?'𐂷",W?b'digH\QEY5J3o9ΒJ5WaLC#qV9mL6qR;Uz+^6Zl ~U67v2g;eWG^ `.w]٧a7YV0UTۺ9w槄.-om?@"m(c~:UرE P{u"Љ}19XM,$,mu,fRc<6(=J=ь?~gظF_5i!Uv@C2 6^?lr,L%IhLl] T(ByXr0?k ŲPu<,r[uJe&=CL)?CgV< 2]/!;Νo ,m3*ozcnx:pO9s)-ž^:nU zK9޴\6'ywF59k6[hRKsTbwe*:p􅸵$sκIT)8Ș HY `VwGJ4iKpiUvôŅ׹xoeIk B4?u3 h:<W1{S듕7YX!"!J!$&1!?T[5LӨ ntOd]Tc[ ]<_%,`OicU %5D1Xu>X}ޅ[|6?X*"^D<4;jWIj'}r-G ¨xsBgFe<˷ @YaJuƣ;NTբspΞ8؎,R@UO}@Q/[ I%:3Tq%,O(~8ʽ[m)WD#u!] ,weS΋1/BIAN濖 1uDrGoVEKŜ{2ںjymn]OE:EGK;SM;._ޭ"B; _R3їVݢHe #74xJxؗy0V2oD,_gE/[6R2KmV*o.5F _-<")Gj{a05]F Xqמ7OW<='Մ?(l=0晝5z qo]ZV#؏J< p2>J;uS*;gB:3QӒ@4YI}#LS;#3z !9 溭KKFBФPUK Ѣ=C'`γ- WƗ BsdBOٍw^[m}uDCM0eo<|K>hmr:_=Ǚ -,lþfe V`$Q)nohV ZAK/&#prOG(e"fJ7ՊmZgBn ./uAY`SC6y ;0P?=A:&nvEyZ9|'k$š3,Q[ d}M*sC"^T.b$\Gv F'>hQlOoMb JaXec뼲yL=]X}_Q#jXvuecހ>'[j'k,E-]'KCO[D*5JߘaNs2p; 4<rW3{MH}Oz @`LlD5GfwǠ|\\t좦n G\Iy]gz$!F v 8-bN™@2 t'p-,d%xU6]OP\2NH00TzNZ-aޝXSj;gL3roe%6Y /곱5jFʋӝ6QN ɂ[v|ʦ4d뻞qUhlp,7Bdb +[!enTG] ;Iӏ^` Utj3 y sw ǀYE8G쩽LH#{>5Ӡ-?,JSQn.uJ˙`͋]d42ᭋ$}2݌Ѧ H%8+`ՀLS[l64/s 'MYcٮt րLLR4s G/)ZV#h1FBEm-K@x=qXknp7#@^ҫ`Xrg@(49@}33ց.^mN'C\ݲOhP=d1RJa;MF-qgjy"^~{n!/֒xf^fDo/ϖI^^?5hA\ӲZWs;!'n Ycu]//%%.=/2"P!!IK%W^A?J_0ȴ]0\* Ql!lK"MW} 1Pd8jbWrbf<xswT{sNQ]"]i?P3f{I(c(dq}yGDяҢ LH8O?` %1 5a]Wi^4q%ʗ2 BMF(i#uk(XB;'RűMggAMW;kAW%wyQ֙Jc"1a}Xq8BK8P5=lqƱWj,R_.MN,rG,RC8:MeעB1h[_Mꌪb' ×+[tdH݅"׉ fLbf_B~>u}:1`E9R_ċ =J>8W-H ^''1Tt<^V{Gwfq>K+YzНF{dŃ_ᶉ ^HEc$bNʱkհNn0^t؆aKqj_IK_& F) 623LP?CtMkZ۔Wj_E{lQpAƠhy\`p4"O z<73RVŌ6E SG"$B> [ X2\)bX=u+$_o`:sU{`$=A6"gA ;>TLU,}Hem3s Uye_vo BZmu0b5jj00[8i[ 4F&AC[dE^sx3eSpP <3Tfr^"?^"f_;:,L[ UKDiC&޻@X}n~ISSG+gA6iLOw k6iEk+ ޕvcyv#)u>d舠}t(ĸ LR"ZtjAwzXޥ@] BC${W*=/2/oI q73q pl7NFhslBzefP4:PBAlT[JNm6xǻ _=Wr2 ?4'w`fIJ8^Ya?L<>(Q >!ރt43<+`^G{#0^V}N;&|@ɷgGorJ5FoXU5i}µ'/ԓm AWuf꠬CX s2zIJA(!gSr*o6{qQm9BXay=l/pS\g!񈵓/ =E<>O;-*Z<`zck&1]3n1Д y,3)[R1|ԑ{Fb: #o6t cɮVz.w=CVX@ [l sHyE{M̲OJf痻oIkאv`!(=}; XP.E*& 9S"ьtǺ:ƨȯIwL!,>KQ5qԑp/ߒ93DP2豦 7#Lj @Ɩ稧2 ˦uU¥^G;}=:QcS /l.#zaJԾ[%oNf}9jˮ,ܖ __ž4VR%y #fVرCE/?'Sj'唐 YيDRF[rD!, cGŧCc^siaH5yoJU:dCe`|*lf2/ xebBmZ61hB׾{ȅ(Y(aq7 0-S ÕX^9GxK니LVjVApfI4aQm}sWŊ45vcT?P㡩jƃWl >tfLIIPŷӽ@hfՔ o}H9Y&}Ism`t/3gao;YkJ[/|W b4Ssy)HN`Bj=>}Ds3rX2?Xk_q MyxYpIB(Ӵ1P5⏝ |"Q M-",A13(nۧLmOUaE‘!,׿{zIN$=xOCX[cvd,ǁσZ 4"jFpd ώڬI[s'dž=ds>B,mB/(Gۆe &{XvuM)̾7S c{R65ihBV FKn񎀉]޸JLyNh A<EgsZ:*l.Q "#uZ.@3kGoXJne$$+b^^P;{Oh4MHpN 0a`ɫjg`aS`$w"~ n=ob]|׍x|27XOe 1#췉#Oׂxī.n)V+gwv9;)SHd7:3 Dqi=J [g+;{GA1ʭ6lH:NCW2VgFlFVY?t s [.Ipqʰ|ly#HtO>wm`GF`{7^O[@XɱhŘ2je4&Θ]| ?#n~f|b!J_}ʤB9oX`}T- 4C: My>ٵ &pLDQ gGB~$Hd9}"#׃lLU\A@ ^_OBnKȄZ[M7K+;  *tq=+v`qV^ߤmч&&Ԓir牠GER龀w9KSX=&g-eIfSDIKT)F7PgaE;|V3)>yC`[(R:gadUSV~F |G?0폞))VIO;mi+-|VCmGanYKT ZMq#6c >TǼ~"(МO*YgMW"sjuSGTIE?+k>is.{Ft|TAKF38mb"UFg^=̇]?/]EӸ)^}f"a$\z^q>y]8:xlalMkUF3$] ,ܾ1>%?ܖH R5Nǥ~#Tu 3V2HǍͽ*ҹ Hd&+rQ_1vζ(hgþBBnf+q 7;ki?Z4[e;/~_r "@f8?\s;&*6/3{W*Emk}ZC|ǓŤ (UzɃWc6nP`h!!D4)ȉ+iǂ)|Ke0ƭB58QσW}FbPO|aGhybz@ U}b])K0qmԣGv4Eya_epK@ [bY0S"0894R#kZodp#+RڦY\Mƕ2<ν#F0!fW_9Ybٮ) ٌ3Q{";jϕ>^m[S٘$$wD+&.uFf۹bm[|Fzh>t.%8ƍ'O/{xEh./Zʭ!Z~nJmVVHƺ~WSI-9P}qq,ΜU!.~Дv|e\C<B9^q\O;Mcf.^U bM\͒~]/Vuc_jS{A@oY;.=an*)'GxnGJzWM],tpzoGjFPuMx7k(Hk2HVzE3qQP S޲Jb 3@ ȻKfW]L8ibqË ?: \[E3l15.Z (j$yF&Q3 BMb =4[́MvU %5 rOG@iQX9!eʩk)۠Vm-ꒄ{@ Oyά~pQ@V {љn08vϔA̸حu|DSC'icB=~-4&C%= Mpˀ¾+"_!oQQTg;"9淼)gSdac]Iah;yXussn,6r|DQD:WZl 4nKd>l {\v Q㠖qDPv>>Lm'!lA7PH_#Mb)1fGlvi0 .^1`q0ȓ~ $a 2dW#;(16j?uu n^MN2q|(qm:d+*|4|DSLחKm4M++_Am_LJ]^.{@v Z^V&aUwT 6to^id]׾8 g#&^ioQ!U;K: /?)a-Z;Vz}mꟋqz@r%7Uϱ,Id3َN;S\^e.a0l-䆞h5AH@?[:>ZASu5O+ptl!J@VqEdV׵L›c a`L4!H£S**i*;WSV`[fDFg@]WX5FԷ9ӧ%@owh#wI9wnR K1B|6'ʪm48 tc`ǒ%EY-u)5،a+E1)kHES_-qrw75m5M5u0YJ3%Lg9xS8fosg9N[K{k1fiO~3sр3xY(öJDSg#phϤ?x2 {xi3ykCo3 V" sۑ>ʐCf|A| f Js acsT(x/Zc+nvGlu7aMUh? GKVʎSp B#E|U%ɻGc*'a8?ÎG1#ފ#yvDPaR~ c LNn{fc,. eo<.\UAz 3xs<,]&\G!07i_1k . IS]<~f=g <!E5.,@1vu@#=c3;֑|RL:1pCy]{ /TL;i8BS+ߍ9!N:qTMltvU_V.Gģ=[77 foysz<65TON8A_o-]e.=BgYF"d/UZSN3gaL^R t?'gRpsC=}*^,yenȌ$B"ЂjJ?h?8l$^Cf 0Fk! IG B@;ì%(f/G#bzH_ScnAYWCV0-2&DrE-FToWكtg|!*)c2q"Y\O-L|* Xx}&ЗˑfFAf_+E%mȿo UZ5 i1;ӠO鍅xa #Bɔ+QZ'".%n e VUYq@RipSxЕ0[#s VEM/\`Ey 2d1@ 96qӷjs!C$h% 1~}+{s'ܶ)RTG(~Wƛ~|szeE>2͓<& |d`t2fHFjJ=xܶ\˸]>@)U֞̇QtSm +Smp{E;A- !PC_̆|>$ =n![I2;B㤝-oH.aN?uT 0Րx(X|>O-2ci8XW:ZLx5m\u5.)WDAŮ}%2ַ.:ihV zmGA[{l-`@:4ã1'J0"owW.2jcaK*sra$OsjKFuC\O^6>b#c*܎>G q (-R0{cb[geƖq#6tTzV'x<;p Q8Kgu/cs/ gQ-e"+"&VNS@8P|;y0Z;92N \(g0Rg!8XUX瞒" N鉣I :X'ڙ"4ͷK('p~hNTr3$Wډ"4f{}^55ۨhVrL&-[Crf :Y8/G}k\T u{E4N{#UPw :k ~%,ԎI1֠f.hd:8*XTD)-ppXayb:Cp*" r6^˰ Tt;ͭߤ:Ti?ye2֩爁tx_:4U2*Tlc"DmLg*MhM!Ogw/Z]-#'oo^9vתQ9,|@'P}fn45߿7 M-bS%3.ƭC"*7xWv\]اb1IjhN4Hζ]u Ԗ`}6𐐺}ƻn;ފeb5.4IH ge4>ǡ 蘸 M߃FmEH% ъ>ϹSqJ3]V ![z⠃{t#ז'2E ஛Opۨ)yU9A|n)zN7A!{"+"8lGH 4A.ao(lهƂfGa\FiIP|u3%k0q6d4DŔ/ k-ݞL>zsreNT-bI%EM\9ļN9unV=)-]LPǹW,CU@Noc-!ZuX޸;2B8cq(bEUCg~NZ836FTjY GaݏNձ^!pa `"6ΝUȧxڌ'yDx߇%Kc 7/TE4S U>ylx零0'x^ O8e.Q[a0D* Vhhg~/8DB". Fv!ՙL!F-%ʒ$w ɟ>niS-ь _&StQDﱝ@DLUez,j':+bu1}Nu]mC" y- gK/k]]:$fx/PQ)3c_->P Kij' x"2g\&TnCwuGC;# M2Vjkْ7֫?`U"R" \S)w4 sPϞe%>)eL iV!rQĜy,ZABooe9V'Lh!-*:%n4ʪ@zvQgM TXl,|̇CE]-@rPj.L/С⻏0wBrs*_(!D`$>gDi5hAs켔#wf]=-aZXDꯆ ZU%Pif|L:k;T\WjJ5!kZ/h| fE(JygW;EL `.(F' p8PTs.B]+RR~ )o̲ |1$Lp?+tJ~TRwzp")엹4~ZfJsԁFJQQVGn2[ xxz"%x} _`u2 CFi5F`؝j)* mZȽ&G’U,}E7T_6L uWH%+D(y ;P9ue Kyc,: KU(P"Rh6홦#kdQlj=B<IUL؎ ?h7 `ypY2 [~DQ]~22 9Kp'\'Bt+7Xo:V9YK]yRM#i;a'x^#\̯kJٿ;YJE5,p ?걬:hgFd .1arxF50\ҏ?Z{zу(?GtLiQӫt [A!&Tbu?f*߉$McrKua^RO(S[$`ta5 ?q8QG,~:'HO+*pn>L~\*9MNL>S a.|&n:UKv2o@ ;;]X+$"9w19I+'cxɦAdxëz@X@4Px5slTeqL$DT ~D=h=M3:H4o.̉0@|5Hh8R.r=I. ?-,6f!*(_\U#3ofVKb`75[Y%)3Q wMh&S2vx~Ɲ\ΑN,FOiF4s=A!)O#W70 C/E" xUW(6ڵpu$>'5׼ʝkYbe'6 ^p:?hk~FIsCe.@Gehj+oO¿+De~WͅRa&'Qs.N&Gmp}/`_Jɔ–M&^;.H1&o \D\{h=aEY(v +j/~xܫ5'E$]-6R]Qeb"o{DWq/ .I,4955#x˳wb$..&AبS8_G0 FXʔElt/ ܴX ~.BZO`4r^ŀh0}gBI[/ʄZ>l=68_CG]$A kCiGWc4=>P5as'7ɒJ_&]Kt`e9V<  ev1TMtʩ9|̋:1FۚVLwSMLҚ*ޒr pul,kD%g/bPgEﭕRE,I|bF$7dR=n؆8 F#|(L@ f!B萋k8SzUN~@aL6Z!r*eF %O4{ܫ^. SϥzVLt2*N qU^GKt^B^LBi n[$󽦒$gP\eͧ;_uRw3)RVwEUJ4Wy; QCtRD 6Ӵ~x&Xf)I< ys0ÕnF;bER$s4#k ۙQGoUͪo[)a#M?A*( 4Ð6Sٗ4'h%ODۈ?keUɯG=^3Y;U] ,z]\̾wde_2w~|Q >2HPĝ޿]ҁߚ <tPrtlܙĘ؇3ٍv j};n :j.kRAoިܣ@'AwVvC1 3M2J Rvϭ[H:=;H.uo~3~s&Kvnp,8G}Ipe(u]M]:.5AgL23l ##3AQPk6H(? I-)]i(2TAwdRY/j!@k/xɐKe(0g>% pMm6S4#J,İV/瓩٩R:vɂL%Rt`~ V&#Lёx |8Ь ]{sѰBSI37j!>irN-jmlGF)_,.yЄI }Ŭ8嬭ۻy@|[;C o:޹~PF.ƒWP2=i0ءu5_iU+l;!vga̳ndf2֔YP~JbBbo~HCm=_Xd8 MTG#?uPOMRu(uSזҤ}*/#cH)w;+_$u`j;HF` :?N`XG:2m,`[-PkF*8]i~X W5 xj 瀕CA!QYN|yu ,5Lp[+'~QaH+D$z4jU,̊-8 Y0/;Է}"9U)@ֽ n8Lbёj,KZ?Mq%[ܩ6U S`VV`%%: }ߵ]ϠxFS*KF%Ff 7SEM(% Pdr ,ekBQAzwՎyov eBZ;2e5CO wtNzs2Bkm#wc3]P<6y6EԠ譳ٰfGQ7&OLtznDz=V~O/߿׏"*H='b9rNTzM[e_&p4iV&jAtX1 6oA=n;?TE_rfll7=ŭT"|$š.} b0l^-2ѽ"5 ?Pf1͹Զ~k͗/ I٫c{e1I*T*vh^:7N2xtmu{e1rDxK-$?{w/JB?*n엳>6E)xC5, UC> 2LLdEQ?yBM)s[ -hN^kU&>=O~Ǝ gRf;+U{8VTVfM]8XMQ d$͓Q~a#VNח&"Z|zy L iӲ;G+:XgJ|`&l ~:¿;BB_in4 h=Uq IV3 pEe4E &zUWG&m L9KKJ9_˲M3(>etTQ2[г</l;f.b UчckhB<N'tlIV?AYu`yyHcIG\ʴk6>墚ɕ+?ɤ2^m{f.6+1rUeZJinԁwѵV2ehgX`UҝEQxWXGG)&> PぱAb\a.)%&ܽ{n+.nO4'Z$E<$>(!vGdL)qx⅊T: nSy5߰ Wnĕ@!AIH2`N8Nh>;2gcd%DB-wh \OWuIpٛuJEh mŠoh q+6BaRkL۝ReM~d!=Nf^~ Y1lhsK9}l5.h&7;HO9w 6^ 1~0in~k6;$2aOwV2i-S̞c!ԝ.<:H!!2 P'Mj!hnw{NFߑ[G{39M9#I/Mhk=ʚy 4RρyƄ|v"oQ1ItaF=)pKAr!B@fKv\ܕV͉oوYhM3ĆS ǽUNYFv _sD\JhjT!ʈ*Gy)̃˘n _ ĺX w17Yddxm3 O[Y7ªBUsm{pHP%"ksq|lldJEZql*u{/.g&cKGď\'װKY\c2 /'C'I (>|g Qf'+ `b0=9ʹDkv4jiOw`:F4xXev[`HJ#Z(RW.4%("?KEq}~T06;(+34X=}V=`28J\6g<+V) LE%[<Uo;KRbƝAR"P@[kf.H$X!(i=k?P0p}4߼WZơ24Oq**kL8\cȊx,e7ȣ䓚fvKZw{*rP)*D]NWë WhUKCyb)m++w]U#*T}Fsn1FFe(/e%b9ߤRn_CyHi| 6"ukW_vUVwwf_rNZuR=D->Hx+mv(aqa3ݖD[6; eVKw[.x;Fߴ̕K|c%34'C$QW(^7˂p)#T#:{B; |ie=/&KI]"TrR1N>|qXA{f盋wsV8%=!Vay9QT$ɞJrOU8"tl~ + (( 're œ?DJaʰג @~nԭ1mWdE^BC^a35~^d~-fN٢2FWziwڗ$X4:GRAt*Z(EGljsA5U_0 `o.g|u Zz٘NNg&͒B8_2gwv:w 3  $BX9N?J,f{ʖ8?l &v+Ƞ{pi3ow/igmc#H>^4j?[p9v0Dj\b5U.!R@K-HB=yid8)pX w\go7cGɔΉr7? BGV>2+`rHmkVo$(po)TWF Zו>Ĕa|x:;x^1ŗː-t#_0|a{@u35DjZ*|t\s_!gT4 V}{~9V=ul'_\Ikl*g6wX.Zq(\Z~o}q ݅fHy}xlu{69OPܣ*;UWEk,4߈_2%8*img ȳ3'٦|tҘk'6 &nI3t5صFaR2\2lz_'O4-wtZJTՃ۩."RúW?e)>:hDR [ P+ڇ*~^7%զįAp$Ɂ6Yo^۟, Xh8fqGCYZHk~0tU 36i$IGVK,y!"_7(/ŵZł?jhpASN9su{0&e QstD9lwSE8}+;vÇ船#$PS}DAP+p߽x+ToamoSKBPl,"Ľ̥x;eW73sOE ofX^Z}bGJ$*#B|ҡ-~1V#'nQvKKʪ#̼Ԍj'IM(ݰϼaT*.}KVp': GJ erAɀL,3ё5Λ-"FyOcVE.*fNEgB%kZW;b 溨l?< D;<,ro3pNM]Yf]X5]0 S4WзOj]k%1m}o C5_I1wi0ԍ:-j IA?xޒXhse"N~Pdug.-U -,u 1Ze2/4ySQ(ސMɛe),r$霺:&&US%+{b%NHHT#(~t7b9{<T Yt]t,AUR%v?%_?B;t>ynݷh!&L֜[D*lFe8Mo4%L]]oov$ 'ۨr! ~Z]9<*h ~x5qoIxKG~Z!+zU?S;lFQxs3DS*3{otrU(QɕKѬ:g+ [Ǝ.vQsd:x눞Jtom8!,NO"'X٨ld 6Ph| >p?Շ ]?ay =?\]f[lHvs?rK1V6Ō 菱EàA[{_M ^5Em5AڴTQMl'`Um^ыsRZ/nzS9TFb5^ڑ+Q@&µi0˫gzT[U}{#~ҥYPX ~6='kpT ^=_>oqvG\(Iր/:GyX֬0i)%;tzKM!9Ż@3ANťm~ d]#Ҳg;_ae 1z`&1WD쁽x"(Ω:4Sԉw~ù j"DMZdCvm%d̈4zajL{Ɛ"N4M7^]߄0fҠbdFx1~~\7nrS V5nsHԴ©NNv=TOcGQKpKtjj:tLS~>e\19E#[?k6-^1'DJ< ".=[;BYt 25QD'ҩ~=} ϴTp7XhiEb>)N0I*/9x e#6H?k y$Re?*9\3i8ڠOm_*=˥IBkׯS~XF,Yr 8j2PzVJ}8!cj}4݁YMb뭣 kx>27wt^Յ*As䑙$NnlC$5d1#jKaz8J\'+qU<H`%*c+SqYWhr:w?L7GJI&y@A  -ՙ+9Zqyx".ΞK`8LLu4ƈ.5`@ϭGԦڻ®FeF Z@:t#9!/O>x3oió顯OiZ5EYmQ&Uѳ;[I8~`ZfZk-46^rWk--_%Q+-0Y&2/Ji $]pF~lT;ٖk@=9$4^,~E]O]ҊYPD9oܭ-eÉ4y a +Ri0adiÙ.!9r50UQHL$g>$hWMcb@a$_p&'ptRQZмEP{]~><IT4"㪲r=ȿ63qZעoʗ{5fCmMrLNӯ pAA+/Y]J)1!o^bwFpϕ֡cQe=f O PH]]m膭xZf/#Ufa/~x\hA yg_+O$i>: F۞;!ِo7,aZ~z:; 4Qm SUjpZV)K"w"!\}lRl"7W|ͦBTM˩7XO*xE>8=:un77]be}#9ސbM^"Q^ߙ<2DP3q޺@bBÐIBɡxg(XYeL䫜Ju)3q.&!Aev]`l_x~j !|f< ,U:1mis7d;ʏk|ow Huwk?at[ߨDhP+uJswhEW_skspP.Y38 ׆[G n=_|EY#M?cBۤ \t}[–" nhGR-_} 0gg嬀~$d֓inVgqp< 4< q'i9F_`nj!Ol nFhԴ$K5Zz$/7jJZ'C. 蝽pppV*? IÅuA!C׉'C:cTM(mÑh gC]g66s2;GJx"ܰgHAm\8˴˿Twh(cTe5V|dG˷S9[]zz5ް9169NPsPA .V){P2;=ێ+q*%eB%]Q̭'s絛.ٔ="2ȱq{Qυ_VZ )v܍Nz " `)u+T3Nކsv2@;)1aH7ϾޚЭ (MdAqS*lqVWӡw*7wV3Q;Z&aa u xF66]c!;Au8[EB^) cZ :'Gow˰mAP8ye6IHЈMY~Ŋ>`QgmGub|Vlю􆊁m^}u"ϒvֹ$w+kaݻgbG!xq8Meed1zk? env.N{hbEwMq] ]r5N1P( ZVƩcCΑǎ;KG\:v/]č#@Vep}_P%= bHU6PP20ڊ"~A~a``#(iʚs%,}@qU/5l[8RrRKX|kYjƔܛ[gC0'Atۅf9NNC5cn`+Z-`I˦| n΢ n=b U@} TBc'oS/pO-x֮˰^hԕ "vAu~O`1s@eBA|4XI6+;w^V?H:ўXA6Vñpyw=B~FfzfBL-FRt"je-vg̷ɈSu3FI޶`lX).]z$Krq@DJe7#(iU;5"?tWGnxD2Wox@[TaYn@bostV ^j鰪Q-,e0Ã]W@Kcg$5 EDׇ(evE":B=5g*p^Ktқ0a0d#s"C5="Z J@6K?D}Y=Q0Gs,R=Dbkm~ L'Q!3*d=nWz?w6{|=*Vbpupa4CO}rIn\4XAq#`bvGgRw]i+=,@P0-/Q"tG)7 hD gK5;~˓yGEW߆!3V=Y |BkeҴx'FL.q 32r yLC #Aq )Vp9 ۰:[ID'U%p=,zJܵ{F@T $$Hz8Y[3 ~qwZ`\yu<0FPkR]4=𰦏o؏v@uzTjh(VKnJ sRj׺83WC#< A D '/m|+~Kժ`.hP/fNqw=hטżA@vץw=W E+(,Ĩ'سA_)ūS9E5hh!r sfv@&zF:{_09OD>9n1jIZwj%@~ ,DIzq.X5-v{OC WҔn@7zg,Ž:ǚj Y ktq< '΍i2@\"{ e*Sl;)'lK =P[p`Ttἴ H}1m3ZaK|.-!M)bONug)@x#:Z~dCT0T{k0{DH)buΓ+ivӭpk:l4_a0)>5{̓=V E'v`ٵr .A xWʢ_ꕣ;[$K'.kgm7M:zKv櫻6(?vNbRv5:#n]%h-1:?FB$|>ҧ>kkvyDA>͊غa 0q n 'xI+(NХ$΢ohDI.JD។> Hvff2ګCz^ƾDړh=~DUyь bI=k=Z6yt 0HZb覝 kįQז"pͺiTӵϏætbd0ʵ^V^Z.~Cf9bzY{J ʈJ"4XLxڤc E Vq5JC3[5ݵƏ!9l7ˉFxǵ1$,N8Ӯ>izhLڈ@U\%uCVP[J&Okm80/}ȭlYar)A&^3xF_:{<4rqW[:Kg峮e ӈ,G=!y kakh|A!7͒^OC/ 8nBFyvXWKA^ZhJÚ6AYZZަT2<-_[g#a>!_gmLY8BY|0x>̏{=m2~C"/}ׯ)xZ.ɴkrx霵|tm$B@|nޚ^ohDT̲P>w<)˲~4D'[|`;<q]tڎȍԀ4xngۅ ĀP,yc1fj!ju^*i@ZbT ?HR ~Y!Zkx(d*Ň!y93>'J,IEզZ\9_$!H^q \D&i$֪2) =G'*V9#} aɋ[1?ޯ:I 绬c & vGS9ZL0(+핗!tF)7ޱ0k# DAE/]q8F͡t$՜UT`8pQʻ29ş.A +SzCy򬺐Os>ygi#F-Tئ1DYI?^G?Эn.2(\,qUAҼxڼ[MVaX|̈́eGYECc-carߜduk$]CVk_kf櫚)o<_\O A◯L'rQ7AX&^ڶLe$4K( 1VViݸ׹kκn1N۷I4M -mȮ|aVVfmp:,6:*seryD;OBZ"Khʞ+LY8| >X(桘cIKb6@(tdMz6i49.& -iYGi4)xT|b<հِӑo"*Ƿm#ÍB<6rs<p6Yԥ8Hj$x$K1i$ aӜY b^9z:$+mnjS<޴ \$ b^ phʝ݀wβsEikNFE8"*z[\357Wg=4gs2䙢A6C]K9L)MեRG"w49s{ܑ'c;~EӑE.'9=Lm9/gefAJЊVt\`Q+DQa:=w8ZCAD1u J;fWxg []e"G{M)8ֻc#y3?-V єbRR)ee4BsNs)yzOȓ1w &,qS(s!3sȀXsє@P1U=\=!1PdjQxpFGg t5T?)/uqȺhsE#qx$H/ i7\܍h13Swv>U ^KMBC=NRzqb䭽[ҫ~AqfS=iM)8D%etvX{K;K_-풆F;4 !&]~2Ga; ]L|`P"$;Vڵ'6(u/FYw$!͘CA( ;YC&7}֡fEVO!ຊ՗TIvn/5K5\hgJYC Neڤ0GWPEy N3ku5@s[E\?Qh֑%*9$gMjcK^;S35'06!g_RMI"B^!*x]=}tT ij`$J@ p _ʥhz(✼JkΫ4(/h3Z*V'©-"9 1YBB")/ xm[:97()i!6[Lx6/'zŁ_+@rҠWVG|ŏZҋ«OH W [%5@%(k;>SH^{;jU=6=W@3 ga+uƕM7zo!S= X<4){`0>qI#^î dl/% L'GU(J{5嶗[(H/Gvw ostN`T WlJdЖR.C!/4[d֚eƿj/ R7a,0V:}a$A3llhщ`1GVs2 Cc̐ TQֳc8Ϲ!ֺ?X"csP1fyrz3,y& &7D.bT%JR+I?DZPw?Nb&orq Ҷ(M_j4/Fo0ă Ec2eKEx/}N=.4pVyt o6vaZ LjZ|M[Xokuk{a@8:"?Lک0gI99v2m+:RxE1wSڧX,GDIhB}8;-4, D0z{J+sx4hm}R!"zFxw@Z/џF<I!ro܊yϨL}YL<dX.Pפ#m[H]{NժPྋtxeQ0T/j [ʖ}|p+xt亰.Mz Gg籹l_hG`FϟzMYYc/GrLWx U*w(!Ι 7Y$N꨼[/CplwqA _ +   e*ؼ{ϾZU?'kh9<ś<g-l,Ny|0uI&H#]xqr6J}ӂf] I^_ Na U3$_UR^ڄjcX|?Ϥrw%n$`.-?юfk c'̿QC%M3R}CN& 3Vh M2P vdf %/̘?|_5Q]0\d7Ot$ӎib>0+ 0#򉓶eϖUO *pn @Q)`/TlX}dG}Dkw3I@[..m6d&$xB c:ٙgaů3lpRFTv'䝐eK%$:29ǭ{">\  W{3ŞXj0+ԍi![vQhf|&%~nq8Ix?gC(z(z)|([B6_& t2y=Š j-kN 9:;BV3{hh"e4%}\0eAB)v4a,jl鈄^Q?| tͬ,"< e{h6CPg88-㹾"WtPM1?DٳK,@e IuUð}O{"3!7&1ĸ7۩B¸q11<]FnCww_Q8eƄFwtؖ2G2!x 9hJl֋W4i{Jp+#L6P{rnzUd4 /Y՘Z}CA3:ossL Ih6k>&@AmTT'͵?J¡d?ʉQ8*Uҿp&J,7W^f~[vo#5 xbplr D#C~P|Gtc,0W0bI7*S#rۻW믦P+K;j U( T~d&O$v3A+zA6 p|aI,T ѹ gWɓE&Y]`jX ~? N-ZٽP()KSzf>pd鮌nRٔ y#xK @&Ty}Pӻ{RڜFUbUUbhQNJ圥jaOFrM)Ij'`qr:Z猷8]?YZ-韧(DXzs6a12gVn&b,K(m0x@5v\Z6>ӄbbUFvB݁L"1t|o1jCӞQU9x>QtljNne>y͍Hs]J.umax05M7vMbG4 [ >_òwF%_ #9+PSXNȚ VI 8_bmVƓ$iKg$r sR͍ /?f Q5`_Xɖ CL=9g|j"F\5їCxN:ʕʬ79fZ?6AeɭuWnKc;.0ֳ7Á(n[ o~ 0;B?خ/Fj ʖ@N@K8&RW4od4س^7e,LB0D;8T>>9l\Eň¢ uO.V}M< c"dl~?1$n$8cuHzZnYEk}͂:T ˔ԥ߶|,̝J8r֪ XfSΕl ?I}W @JGA4DWJڅi_dRf#?é S`4{X<}5]Y9g\hr br!LӞǿC6(wE4wUj[M2f4jMuD-zQ$,Y+w#5~EPsI6 >+4jSNBpD8[[7_q>q7=Iqڰ TRkj7?'41 <(?b3Ğpkdo%soK7>aF 7 A=3%F  H/icw- IpܜnWA1rjnƪнs/'1l M=io| \F=JIIeQ*)I_-bh9dFl%tJ\9*L`),D&)HIVSi)C>FB'uq59RP0BDk 6M0!~DܰW<8˜R>H'[9މ90]PcVZ6"MN^4a KY,., Ŀ~9)C@&%+\Kد6jG4M5҃ś"\&S!r9~wd[YO!uu#.1Lhd"2m/RS^BMAs1gәDD؛9iF5ޠ3O>Zm6ezx,?+JHwMCˬ gt+wI?W0^E`i\4|GbcywLn&M>b@vSxC?v]JyѦŐt ^# ]cnG<)k&T^899N]{v+d GD&Ҕ` FRHMEo0W^7?*,j%@h#Ng1HP^#0[8G6*vSh3I*0ОzzoD}N [dTnt?CkJ!QTĽ M?%ꟈSats;oHUywj}?Qlmh=,_,BOZPak pt*M-dOpt|t/)a&uo)kYFX)PZ杫ץȧ+;՜ȓZ]f?_+N.ebl܇F;)m}8X:\̝l}+ة؀>PFu6\wh6X"bv*'%tj5ΗuT]LJ肸>{7R}y6WbP\2LL٫ҫ,ԛY#3U' xK3Kx4uCG҂ԧw +oΔО`йDs?AWF]P;|}?s>Hl O鴐dW~]VV[#!hCh݇p?q0Zؼ1shFWͦv2ݗigcB^Qp-~HTpzhEl/^Y>)FaDv9*lIAo+1+ -@9^,b7'UО%ӋH%.(~߈h!Ap9I6hG8oV^K+Exo㌼8=^GƺWC_F>yAS 8 DѾX 9c֜v1uYyRdXI">F6$͗$?cK:4 0C}팈b,_Axj} mN 1oUeo7K]~VܢJz i|`B" ʵ)"(e.qؕfw}qO/vm@ށWIGqs[< UIG˝ӗ, 2el)'@ _5 nސ9`{morI>AN%L"Y% s?:2Lfa&D'hY:IskG+gq*#w#sP<(G'{i{DD~#*Pݎ}r}wpBC]b> @+MmbYB1.q|}ތ!z O !|iE loub P9V;5.<- Z *:y^O^8UxqrvɲkO#r8Nq-ɿYcqs# ֈ8k)s^ #.х Q3`F7†x+`mtt4BK'vl '숥P1JQF N(*Ft(JԮ-45uD,pPRI%#A3._h8p曻 Yu=M!B y$H7&rHcH46ksk5m~UaA4 (m0 g<f(0vZ4n?YYV~44a45>LIU,{<~AιN' Fq7W(fT-˸q'mUvİehU /YKϑµp:V5O,Cdjz[a?X+pOgQLT:G$ۏAPѾmgd"*y0%0N%O&{c MfEhX/=c7c62gUo/C5A3[)A&*A_N(0BYdr~G _zHZjPuͦ$ iq HT\?='EsqH۴N! lO}SqA:J`o~h'lU_9EzV(Ks fqKsqg.^F3qƶiQpg<˘* W_oa;(y16 zKq hm\&e)ESAT( 0w-D ׿@Q#Qһ:cŖX Uyتd-eG^38wkK55vQOr%, )1!tc{h-/s1f(7-Gmu !E W9LKc2/0h؃EסaPOrÃy~sC3Bน_$p,s/2=s 㢴PdHM7g@.@o5Mì""i6g90 8D|zRn>&$F=pt,4S@+0 xW: 7]EqarZЎ u[BgMHU'ClH3Hx𖊬߮@C#+OA-^)Cic:h9l|Ki7@(S2ym\>(gUL9nѣ!BdweZ ~^` - 'V־#,C|SR(40ʡ\,.cEGCU. OxC!Gn n٢uod+Ty(TIⅵݢWgcI!t/f Ym'XARNsM2d˅E5@i:KG^FE+AQy )1ʆTy.G5Ԉ9Kd&DCnw\ SݝPzʞ }!3$a2P<$*=W |Ͱ._`|M\e#])Kh6')I7O<1_bsSg*Nf!}qz@T5jG*ũD\Yet@?gR^.)u8u{iD$GoSҮJ2Am讱c>uB?ڌa%%&|ುsh65aKOv M/@$-aZ JB6M. <Gn^@q1AI!QuY&{;_R/Iͩ})D?wyKkj¦sil~v)L5Zz;$W ]$ 5Ώ=dXH)|\[&n((e8~ߡP;QLqra\Yfs S엇eb~ѽ`x4^btcݡ?[9I];DWܩn ej5<#G0@*燾 Ha|(! SY_zl-K>Pb_8[[=7 r/"i^hqA'#9nc<#3pg+-cZHɔQ2a?,Z #&QLju]] 87Wc1a(wkA4Jx(C%VU2yWC)Gš+WyZ_@:~~Qo 0_$ 1yV+>XKL١KGbi6!I8qZ Km= x $+rKgvk$Bcw561isQ>]j:R;TЉ6B 6ELMOgeDMˌ'cwEc*Jby_ayގ^rZ+r@,c졡PDA+hBi]eTUؒI06NN᢭DBbtEfU´Sϣ XtD؞=ϦSXTaq5mo7]9"{v6k!=7QS-7/Z?AWYih?VdUG]FWhU>>US[WT(cU*GAHxW40ypy;hL:2Btձzn@5iQ̺퉒=K^k@&v#s.bD6U(ҷ4]`5x+k~v܏]h%5!.m n~Gfpem?B356m>o ?ITÄǦN`:E^4)e~1/;A\*>%2aH:CThk U=7"yZ @~)GpVxtc/=>``*5NuBzfuhoL,2-vz͂K$p[VR]f٢(l>/p͖ϸ(?ZFԦBciaxso;')Qi8Z>Q͛U+||H!UdiQ@ToC0{F/134ʮto#H8øSв|Cj_%W Ceq edRTŒFC "dU1av. ia[H>񟟝o8EڬM* sz8n$1Cy 8u? Ae{r&wPh ^65X)!HK^Aх=ָ"1U4$Ftwo!o\oŅ5 ,pa#|kzb>ǂ) EřL3=|.6{5'_+&jȟIzGOl7K6|m]DfP-.sڭݦw'sde*3#!}M]ǂ)/uD" cnm:QWB‰N}Jf sn 偞.X@ fyJ*:ƍ2cR<*uN-qo(D/󟠴WC!7Ma(LCv670S7a\ t1`y܀dd_ܺHORX^ݑu U^D <2f¢kCu ℸ@j6 =2(7hP Rf$ԙmgd3MRϣYte}?8RXk9x摂E>?zHx=2mk@ RD,~q|ēls{!!q6kE> @LJ?e.K FauHTˈ̤=bpc_" B:-j_rƻcf۝wH֫7*Q0̡Ud' Dj(ƩAܮU]Z!zGEr=`_ۘ|tp M?y?yMBRG3b,|4G7[V$DI `_:\;i1[c bI_6$ ?始G,/_X k= z,B/)vpE,B }'}/4_bvw .=.=c jԳS%c^d}̢lEsUnT ^h]$10&.^2k~_A#|1+@tD/,l/S^ڔNu>jRujYɥfkzWL?^z{n='&xnXOMn`jtƝ*40*\oJN@jDU̶ݻPHWG#o0(fA˸v&vcWz.F5(Y5/3|?b5g(I4j 5UOx! ԑݲS Rj70}-рnxE*l+S>qSe}x߭uwgbd)O\]ar(KAetj>qX t],Mq_̞dGzI%*{DԆ-c_ 3W<9Ϻ{F*˒L&D};gcҷ 9VMSYs,0vg0K5w2F(s sYH 2_u/#ډb*{_G]nCw JU@ QUaᓿ-jmᓒ脏Au2&jhla2{/#l%xåC̀elm>Un2FQ3 2k#:GXt@tӺWEGوLTp*,th~ZWTaEC_ke<+9nWmͼLGn/Dd2Im?_i֐J R_Zov]ef5HHB3g^jP&ǔ$EF; 0F]33n39zU&4MㇿH)Px"(VѴVQC輱VsP^ nBs8-y[Y`%L2d|bn\WD} BmgP6ƻƞSe8DpL$~6~y.`{S`9h@Wj9FA+X8ST'h.H͏岭VsdT )gX#ܩ,UgV0w:TMjG;I%v:(t4CC} ۪>)p H%zN:d*D?Uݨ@X[jbܼ!h8 jP<~r䄭+li'Rre] R@!S슾< s&vIV_v%2|(yϼ?|c &Gwj2Ԇ- [os. .( -'b3섧 [Z\%oD&M2"A\ ̠CwU,j<3,-8>½V 3+n-PU-V4. *2>[>uMUxQ0"(8NcPۄi@jgǖa^UdS5E \# /.cN8@άBmVaKnM>tK CCpx6NǠlƋQ!Γ~0R pr suN|:#A y+=w#̢ F3j/~SPk/RUTMvpLS C{ZhҾ3h/~ ÿprl㴢MAXcJκY:yH;~u!):y8Poq)Zg5wflE:?">PQ+{x 23-xV〖w`Kyhz]9uaZ[a<(™J [K.P%/JVtcBQىy#ڊQ43]ٍ:{5O+#tFzqtϩKZ[tC\1~2Nj2`W.Rԋ ę%朴\!O dN P,/s_nK:(]r̿ Q{3gl_VPKp?-[”QyePGGIK?mԜ[9E_*4{a!q?W9„AЭWdɫztXks RO9^۷xA7BW>T*`msƇ#3zz:rL\IWG5P]!) qHJt/@JӭS Uqr3Z(Q_`kĹg$߿ZdSS6{Z`Z6ٔbdJK[W+5hH'CM+"p=áccyur73viusBŴD5tR9$/ /k*aaq~;pHGyiU ]s ~c"4ShKzj! fj3p/By_q:.Oi[s[wX)dю/Loǭ>[6ALtz EcCQCْӎZN@_ѨaYQ=h>kᕳrٹQ\WǾs= Ȫm&2z7mjĬ]yOKS ޚ}E=m)24^ebm0;][C_ZEG13H К!8oJxUGp~<7Tyo6A-?BS.iЀ 33)!Ys% TM4"D9Pm={xcRn7YC-dwſ<>N@E\zˑ,Q j Wm/"zfkw?Ec#/ˎ~r.3–1enm/dt0Z)t@6.=Lv Ma<1=;:ayV% XX]iCSϾ$2kEZʚAAV.L-/2JG'lӂc$ȨW<6sh)DzErP (-bQpkʓ{Z2)7Rgj|͹P_"`<*tGRYHS%%1!VZ>4Fl4n JVtBpcwcGVPUrxG8OU}ϚC*|}~]˜&UJxE#?6}!FYR\.IfO$uhQm?ߒ/ 917dK%85U`G&w2Mx9jQQBSPdKZ9M"X72Eqd'`c~>voDݵ^6f(X1Id5oJ,^=_LS Ʊ7Dp;Sy9LM'Z)~!,RHl z(tn5Q\`nQl(^B'C'Am*1u͔9a $jn>sW Tx/KprEz[1We @qpf֟nkw-*֝Ol$^'Cf%@Vŭ,+-c{FŴAFk<m:Ǘ}[Pv<[l@4-Yvt%84 Լ4c_K؜^"D.q׽'@0G C*>ѩ3Ƴ @3鮖6_GZN?L7e_=>sX|&|}9Zn8=׷/$-NKjO'֐kukCqyi曶4,f]=g/IaL]" Oy@&OdA`35Âvu7o k[qIcvXefm)TΗ fЩ8$`Rlwj&rH܄W~gl9.u8s^Y3DޓxxfE%Jp{lZ C qX~O9u{Kaܺ~e/Rp71~v<@)OwďKXwES

PEa;::Mg܍s!۶^E 6i[/&鶦kObC|4,Ş]&O5 z`d0+c&"VI$s䋐[;mbm,$(ԁaYi>h$ wW.{vcnآ֙S2".E WZV9V7zh\w]'2b@gom0] U%E=w TVM9Sw} Q,aĒEgi{ka3s԰fv; ZtnCl=׾И Q2+nUq`lRG#nj(t֤_*E,a qg~d^Zvp@_Nᥪ~?|25B&ƱoUM^@a&KPBvikSkOYq

$ve$>? 3aW-%g[sϦ B;#4TE(*^~+n0cGe,޹og&</}͚@|L|Y|}plo攎At>#{:c̋U>5ϣ*n_u|{­LgS;2>I!.(Lo%UJ飧ȏ66:)䵭~<)lr)xEkHyQGQ#9QjJrDn&Lt!1] O}(˅]QTO4ɲP[ٚT8c8^u__M꺥*JCP^cDGBWS47 UȺ3*}K# P!T *;.Tm&:\ *ϋ&kO6E q|!9-]{jKɇme1!yө[vzk!V\@lH4Af^t=WxΣ/(@W|b0{oi+B]a:=/KW\7U[ɔ7we=Wst<*M/ gk+]*Y cW  rb#QڰT<1Z'|* Ti)HW 7“m"EIMuܤ83LqrH{X}0C¹5MF(y$4Q_,k ?a3 zy2ܢC W&b\:\,oɡЋ|NYfPM2P?;2;# La`W;|=1Vև'۩̈́>RC3IiKB1% 3g.i\Y*aeRѽ{dd`9*I{8b!۸}-K&阿p R[-_X-rֻeX,y+nsOk5%` ~OKj\Ĥm m dr D+E# N)~{He"kɷ-LC'4vJ)d+!6Bʉ(Q5ǖ'D*K wi4֐&)qROݗQlqtċM\PqӰjX}Gղ2rn!dN"5Uuɧ>?4lU cmCv .˖oo3s>MaE1͐\UQ~.Usi@2G}S߀)icJ Q(#< 'j /ZZ6d?lBd&g(/~:\`%YXe&=V"atdFH_X&|m%68ɺ3!A@ӅX \mj>z˔7åz !lOqzjBYA3`ڗ8vR#AW!h' . MNIM?kj@f$bU8T?\].ֻl yvqALˢ?Z+1܈aTZ5 Bܖ,Xk@92`;Xɲ<`1vܨiAOVPi x@+sf<>T?Pǃ_]7cn R|+|zz*GsE>|EĂyԆ'@^2XLw 0 ]%S>5kG{v8d+Zw.U'@x1NU?1Qo"uN oQh@?'Goaő B: |.M6@ TΘU!9 /Qsf/o`YHinP\! +"F\tWg17 &+eo,D-,婷7ܤr'a} Z$h R QO#2}E,ˢsa [UUkpum^`|oy m|83-/2I=UzZtV׶9pATќ _ƟPzY$ 4`.YhҾ׳Uil$B`׳!tt>8쮥#ˮ|mmi%B_8'W-d*܋?fH #v 7hu'r^Be )b'F&*C‹uU Mӥ'mq6-k/L̑O0[SJsԽ0lY19sQC/wf66oÿmP ^ث+mi%d \Z q4;-=GQ&G'ņH, ;Hƶ f(@ @q.i#݉{ !,j c8~46)Ċi-tPt2qtWR9PM?d5Qc.^~eQ%d9}3)! gr96@́k߅ޥr; ɜkȷZj srd9ĴSE}H~JlbkC u(aulM2V*~y(5lko)NvCn&]<2U3n`˦Ҳ'Mw/iɾ:$ PLU _ Zz9s8_CTAyr*եi.%Ջ~CM6JGc5ԾQW cyrXrb4ڡb{E3n+3V0!گn1@Z -$>)5{}(lMQnqMX$} K[NJ͉Iք<11;7|QZ2~Mhs]3Pa bD/!5ȋ3$]`ùLi>9SX mG`PïhtTdRb 矔cjE<ɷO\h+H&E>oS 7ït9mZ37j(H\(_ gɀc˽0VEѼL4]0w1_w/ձS=evuzב~@uȳ5"4&S׽zO ~Wj?J`Ձv:G:3BӞSb7{csmA8⎙>,Y<"11p1Ys{Uu臩샺<;~=TKvythuk)c<ƛ,݁U02kwpjhoMͱ ,(5|qosPC&l~"cCޒ' _Ǯ(%"m7.ksIz|NQ"=hJ+5dL|iʎ1<} "TPH;ܹЂIt,."Y0fr/@lC}Zt}Lik #T%OdyJAC,(TcaG,pr+ulS?Ͷ.:Ķz;TՆ6 z!I'Y ,znBO:"s2(sa4*dKG|#鵿yXx}K$zIy5[FBлqA,47Np |;i2lf]Ć.W{+} nt*4qnPmM$*xC-xAD8>LHIjXP҇450i ߃PcRk4?_'^m 'nOؼ@I<0 &vh^5@8|"gHd%dH<f>O:42i|X]?慯KgpNWv>`kveƺkk5WI{p7tN̝g"B>W%7zo> e1 ɰ?T3pVd|&X '=cW;szl+Z-)ܒؚ\%Gj4X$j6J%Z@Yzalq'H3$zrVm/h@u'k⟍lXLY)/alyC\ __5-3N铼Ҋ5 J+;(8h8AxՉS\ҦqŘ τZ6LթJ8mHÓdΣsʧiz8m*<+Vn$I7U$"&=_mLrO 3A1KyP PvVھr$͟!H=FZXKhwZe2G(w,'W$;'rD嬹W#p"s8.+}哃5?Vޘ" 15 YZ